Bubblewrap
6 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Bubblewrap, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Bubblewrap CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High5
Latest CVEs
The 6 most recently published vulnerabilities affecting Bubblewrap.
- CVE-2026-41163bubblewrap vulnerable to privilege escalation in setuid mode via ptrace7.0
- CVE-2021-4034A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users acc...7.8
- CVE-2020-5291Privilege escalation in setuid mode via user namespaces in Bubblewrap7.2
- CVE-2019-12439bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw ...7.4
- CVE-2017-5226When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an...10.0
- CVE-2016-8659Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.7.0
Product grouping is registry-driven, with AI assist and human review. How it works